The International Association of Privacy Professionals (IAPP) is a professional association for privacy, data protection, and AI governance practitioners, founded in 2000 and headquartered in Portsmouth, New Hampshire. It reports more than 80,000 members across over 150 countries, making it the largest such body by membership. Its activities center on professional credentialing, convening, and publishing rather than policy advocacy; it operates an AI Governance Center, established in 2023 and directed by Ashley Casovan, alongside its longer-standing privacy work.
Overview
| Founded | 2000 |
| Headquarters | Portsmouth, New Hampshire, US |
| Members | 80,000+ across 150+ countries |
| AI Governance Center Director | Ashley Casovan |
IAPP's work falls into three areas: credentialing through professional certifications, convening through conferences, and publishing market analyses and practice reports. It describes itself as a neutral professional body and does not take policy positions, leaving substantive policy to its members and their employers.
Certifications
IAPP administers a set of professional certifications. Its regional privacy certifications are CIPP/US, CIPP/E, CIPP/C, and CIPP/A. CIPM covers privacy management and CIPT covers privacy technology. In 2024 IAPP added the AIGP (AI Governance Professional) certification, administered through its AI Governance Center.
Conferences and publications
IAPP convenes the Global Privacy Summit, AI Governance Global events, and regional events. It publishes market analyses and annual reports, including reports on the AI governance profession ("IAPP AI Governance Professional" reports) and an annual AI Governance Vendor Report (AI Governance Vendor Report), which catalogs the AI compliance vendor market.
AI Governance Center
The AI Governance Center was established in 2023 under Ashley Casovan's leadership as IAPP's AI research and professional development arm, paralleling its Privacy Center. It serves as a convening point for AI governance practitioners, including those at Fortune 500 companies; the credentialing authority for the AIGP certification; and the publisher of IAPP's annual reports on the AI governance profession and vendor market.
The center's creation has been cited as evidence that AI governance is consolidating into a distinct profession: through the AIGP certification and its vendor and practice reports, IAPP has given the field a credential and a recurring market survey where neither previously existed. Its practitioner community spans compliance work across the EU AI Act, US state laws, sector-specific rules, ISO/IEC 42001, and the NIST AI RMF, which has been read as evidence of compliance fragmentation. IAPP members report treating voluntary standards such as ISO/IEC 42001 and the NIST AI RMF as near-binding, a pattern related to the incentives-becoming-obligations account of voluntary frameworks hardening into de facto requirements.
Positioning
IAPP states that, unlike policy-advocacy organizations such as AIN and FLI, it does not take policy positions, confining its role to credentialing and convening. This stance lends its publications credibility as descriptions of the state of the market—who is in it and what they are doing—while limiting its advocacy reach.
Relationships
- supports: IAPP AI Governance Vendor Report 2026 — publisher.
- supports: AI Compliance Industry / Regulatory Fragmentation — direct evidence for the concept.
- related: ISO/IEC 42001 — AI Management System / NIST AI Risk Management Framework (AI RMF 1.0) — standards IAPP certifies against.
- related: Incentives or Obligations? The U.S. Regulatory Approach to Voluntary AI Governance Standards — similar "voluntary becoming binding" theme.
- related: Future of Privacy Forum (FPF) — peer privacy-and-AI organization (FPF is policy-focused, IAPP is profession-focused).